Snapset Fence and Keep Attributes for Cyber Recovery Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems lack effective methods to restrict the utilization of snapsets and ensure their preservation, particularly in the context of cyber intrusion events where data integrity is compromised.
Innovation Solution
The implementation of snapset attributes such as 'keep' and 'fence' attributes, where 'keep' attributes prevent snapshots from being terminated and 'fence' attributes restrict their utilization until data validation, helps ensure snapset preservation and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If snapshots are made available for cyber recovery, then system recovery capability is improved, but risk of utilizing corrupted snapshots increases
Solution Approach 1:
The system performs preliminary validation of snapshot data integrity before making snapshots available for cyber recovery. By checking snapshots in advance and setting appropriate attributes, the system prevents corrupted snapshots from being utilized, thus maintaining recovery capability while eliminating the risk of data corruption propagation
Solution Approach 2:
The patent introduces an intermediary validation mechanism that acts as a mediator between snapshot storage and recovery utilization. This intermediary layer validates snapshot integrity and sets attributes that control whether snapshots can be used for recovery, effectively separating the recovery capability from the risk of corrupted data
2Reliability
If snapshots are preserved indefinitely for recovery, then recovery options are improved, but storage resource consumption increases
Solution Approach 1:
The system dynamically manages snapshot retention by implementing time-based and validation-based attribute settings. Snapshots are preserved with appropriate attributes only for necessary durations and under specific conditions, allowing the system to maintain recovery options while automatically releasing storage resources for snapshots that are no longer needed or valid
Solution Approach 2:
The patent changes the state parameters of snapshots by setting different attributes (such as validity flags, retention periods, and recovery eligibility markers) based on validation results and temporal factors. This parameter-based management enables flexible control over snapshot preservation, balancing recovery availability with storage resource optimization
3Reliability
If attribute-based control is implemented for snapshot management, then snapshot integrity is improved, but system complexity increases
Solution Approach 1:
The system implements a universal attribute framework that serves multiple functions simultaneously: validating snapshot integrity, controlling recovery eligibility, managing retention policies, and tracking validation status. This multi-functional attribute system improves snapshot integrity while avoiding the need for separate complex mechanisms for each function
Data Source
AI summary
Attributes of snapshots are provided that ensure snapshot preservation and enable utilization of snapshots to be restricted. If a cyber intrusion event is detected, fence attributes are set on snapshots that were created after the time of the possible cyber intrusion event to restrict those snapshots from being used for cyber recovery until after the data contained in the snapshots has been validated. If a snapshot is selected for use, the fence attribute is checked and, if set, prevents the snapshot from being used until the data of the snapshot is validated. Additionally, keep attributes are set on snapshots that were created before the possible cyber intrusion event, to preserve those snapshots to prevent the snapshots from termination. If a snapshot is selected for termination, the keep attribute is checked, and if set, prevents the snapshot from being terminated until the keep attribute is reset.


